The case against signing up for anything
The signup form is not there for you. Here is what it costs, and what replacing it with a key actually feels like.
What a signup form is for
It is not there to protect your account. It exists so the company can contact you, measure you, and recover the relationship if you leave. For a privacy product it also creates the exact thing the product claims not to want: a record connecting a human to a service.
Every field is a future breach
Data that exists gets breached eventually. An email address plus a service name is enough for targeted phishing - "your VPN subscription has expired" is convincing when the sender knows you have one. The only field guaranteed never to leak is the one that was never collected.
You cannot lose what you never asked for.
How key-based access works
Instead of a form, you get a randomly generated login and password - letters and digits, made in your browser. That pair is your cabinet. No email to verify, no password to reuse from another site, no security questions whose answers are on your public profile.
The honest trade
We cannot reset your key. There is no address to send a reset link to and no identity check we could run, because we never collected one. Lose the key and the access is gone. That is the actual cost of having no account, and anyone offering both no-KYC and account recovery has quietly kept a record somewhere.
The mitigation is boring: save it to a password manager the moment it appears. In Telegram the bot remembers you, so the key only matters for the web cabinet.
What we still know
Almost nothing: which plan is active, when it expires, and how much data it has used - held in memory to enforce the plan itself. Not who you are, not what you open. The specifics are on the no-logs page .
Cypher VPN - no account, paid in crypto
Three locations, unlimited data, from $1.99 a week or $4.99 a month.